The other day a user asked for 2fa reset on Phabricator and Greg wanted to help with it but he could not ssh to the Phabricator server to run the needed shell command.
I checked and saw that while he is in several admin groups he is not in the one made for Phabricator actions like this, phabricator-admins.
So i made https://gerrit.wikimedia.org/r/#/c/operations/puppet/+/483623/ to suggest adding him.
Realizing that access requests need tickets, here is the one to go with it.
There are already +1s on Gerrit including the current sole member of the group, Andre Klapper.
- - User has signed the L3 Acknowledgement of Wikimedia Server Access Responsibilities Document.
- - User has a valid NDA on file with WMF legal. (This can be checked by Operations via the NDA tracking sheet & is included in all WMF Staff/Contractor hiring.)
- - User has provided the following: wikitech username, preferred shell username, email address, and full reasoning for access (including what commands and/or tasks they expect to perform.
- - User has provided a public SSH key. This ssh key pair should only be used for WMF cluster access, and not share with any other service (this includes not sharing with WMCS access, no shared keys.)
- - access request (or expansion) has sign off of WMF sponsor/manager (sponsor for volunteers, manager for wmf staff)
- - sudo requests: all sudo requests require explicit approval during the weekly operations team meeting. No sudo requests will be approved outside of those meetings without the direct override of the Director of Operations.
- - [Patchset for access request]